Skip to main content

Tag: unit 42

43 articles

Person sits at cluttered desk, looking concerned while on video conference on computer with Microsoft Teams on screen.

Microsoft Teams Targeted in Voice Phishing Campaigns

Beware of voice phishing scams on Microsoft Teams! A recent campaign, dubbed Spring Ring, used fake IT help desk accounts to trick over 150 employees across 10 organizations into granting remote access.

Analyst 207
Senior executive looks concerned standing in front of a window with a blurred laptop screen behind.

AI Reshapes Cyber Threat Landscape, Favoring Attackers

The balance of power in cybersecurity has been dramatically upset, with AI capabilities now favoring attackers and rendering traditional defenses obsolete in the face of machine-speed attacks. This marks a generational shift, where attackers have the upper hand and organizations must adapt to keep up.

Analyst 207
Empty workstation area in a cybersecurity operations center with laptops and network equipment.

AI-Enabled Malware Detected but Not Dominant

The surprising truth about AI-enabled malware: despite collecting 405 samples, only 12 actually appeared on customer endpoints, revealing a significant gap in detection. This finding highlights the limited presence of AI-powered threats in the wild.

Analyst 207
Technicians work in a network operations center with rows of computer servers and networking equipment.

Kimwolf Botnet Evolves to Evade DDoS Detection

The Kimwolf botnet has levelled up its game with a new upgrade, v7, which uses HTTP/2 floods to mimic real browser traffic, making it super tricky to detect as a DDoS attack. This sneaky move lets the botnet build complete browser fingerprints, blurring the line between legit and malicious traffic.

Analyst 207
Dimly lit office cubicle with cluttered desk, scattered papers, and slightly ajar file cabinet.

Identity Compromise Fuels 90% of Cyber Incidents

Nearly 9 out of 10 cyber incidents involve identity compromise, with attackers exploiting weaknesses in credentials, multifactor authentication, and social engineering to gain access to enterprise environments. Identity has become the new front door for cyber threats, making it a critical area of focus for protecting your organization's security.

Analyst 207
ChainDrop Worm Exposes npm Ecosystem Vulnerabilities

ChainDrop Worm Exposes npm Ecosystem Vulnerabilities

A sneaky self-propagating worm called ChainDrop has infected over 400 popular npm packages, putting hundreds of millions of downloads at risk each week and threatening developer workstations, CI runners, and cloud instances. This clever malware hides in plain sight by masquerading as legitimate code, making it a formidable foe in the npm ecosystem.

Analyst 207
Rows of computer racks and monitors in a brightly-lit server room, with a single terminal screen blurred in focus.

Cybercriminals Exploit AI Tokens for Massive Financial Gains

Cybercriminals are raking in millions by exploiting AI tokens, a technique known as token jacking, which allows them to secretly run up huge bills on unsuspecting companies using commercial AI platforms. In one shocking example, token jacking led to nearly $1 million in unauthorized charges before being caught.

Analyst 207
Cluttered developer workspace with MacBook and Xcode project files open.

XCSSET Malware Targets macOS Devs Through Compromised Xcode Projects

macOS developers, beware: XCSSET malware is lurking in compromised Xcode projects, infecting unsuspecting victims through a sneaky four-stage infection chain that can deploy 17 distinct modules. This latest variant has been rewritten to dig deep into your workflow and browser, putting your entire development ecosystem at risk.

Analyst 207
Darkened network operations center with one laptop open, displaying a blurred screen.

Malware Exploits Direct IP Connections to Evade DNS-Based Defenses

Nearly half of malware samples with command-and-control activity connect directly to IP addresses, dodging DNS-based defenses and highlighting a significant blind spot in traditional security measures. This alarming trend was uncovered in an analysis of over 4 million dynamic reports, revealing that 45.32% of malicious code uses direct-to-IP connections to evade detection.

Analyst 207
Cluttered home office desk with a laptop displaying a malware warning, surrounded by papers and everyday objects.

Malware Exploits Google Passkey Sync Flaws

Google's passkeys, touted as a secure alternative to passwords, have been found to have flaws that can be exploited by malware, allowing hackers to access sensitive information. Researchers have discovered three techniques, dubbed Pass-ta-key, that let attackers abuse Google Password Manager's synced passkeys on compromised Windows devices.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit server room with a blurred laptop screen in the foreground.

AI-Powered Attacks Target Vulnerable Servers With Autonomous Exploits

Meet the AI-powered attackers who just took autonomous exploitation to the next level - and here's how researchers uncovered their clever tactics. A China-based threat actor's accidental leak exposed a functional, end-to-end AI-driven attack workflow.

Analyst 207
Rack-mounted router or industrial controller with indicator lights and cables in an urban industrial setting.

Chinese Hackers Leverage DeepSeek for Autonomous Exploits

Meet the sneaky Chinese hackers who've been using an AI-powered tool called DeepSeek to launch autonomous cyber attacks on over 460 targets - and get a glimpse into their clever tactics. With just a single Telegram instruction, DeepSeek can infiltrate and exploit systems all on its own.

Analyst 207
Modern tech lab with people working, sleek workstation and laptop in foreground.

AI Empowers Cyberattacks with Operational Efficiency

As AI continues to evolve, it's crucial to treat AI-driven threats as a top priority, using the technology to supercharge their attacks and compress timelines. AI is being used by attackers to automate routine work, streamline reconnaissance, and shorten development cycles, turning what once took days into operations that can be executed in just hours.

Analyst 207
Person working in office with router and cables in background.

AI Models Expose Millions to Phantom Squatting Phishing Threat

Millions are now at risk of falling prey to a new, rapidly evolving phishing threat called phantom squatting, where attackers exploit AI-generated links to create malicious websites that can evade detection. By registering domains invented by large language models, hackers can create seemingly trustworthy sites that are actually designed to steal sensitive information or spread malware.

Analyst 207
LLMs Expose Software Supply Chain to Phantom Squatting Threat

LLMs Expose Software Supply Chain to Phantom Squatting Threat

Imagine a hidden threat lurking in the software supply chain, where 250,000 "phantom" domains lie waiting to be claimed by malicious actors - a vulnerability uncovered in a staggering 2.1 million URLs generated by LLMs. This phantom squatting threat has the potential to compromise security, and it's essential to understand its scope and impact.

Analyst 207
Government building with technology infrastructure in background.

Chinese Hackers Target Southeast Asia's Energy, Government Sectors

Chinese hackers have launched a stealthy assault on Southeast Asia's energy and government sectors, infiltrating at least ten organizations between October and December 2025. This sophisticated threat, tracked as CL-STA-1062, has been lurking in the shadows since March 2022, using clever tactics like hard-coded encryption keys to evade detection.

Analyst 207
Cluttered marketplace shelf with scattered AI devices, some hidden or obscured, conveying evasion and malicious activity.

Malicious AI Skills Evade Detection on ClawHub Marketplace

Malicious AI skills are slipping through the cracks on ClawHub, with nearly 1 in 5 skills analyzed carrying hidden threats, and a recent audit found a thriving marketplace for bad actors to exploit. Unit 42 uncovered alarming trends, including infostealers and evasion techniques, highlighting the need for vigilance in this rapidly evolving threat landscape.

Analyst 207
Mac computer on cluttered desk with Terminal app open, displaying blurred commands.

MacOS ClickFix Attack Exploits Terminal Commands to Spread Infostealer

Beware of a sneaky new attack on macOS, known as ClickFix, that tricks you into pasting a Terminal command, allowing hackers to silently download and launch info-stealing malware on your device. This cleverly crafted scam starts with a fake CAPTCHA page, convincing victims to unwittingly give attackers a backdoor to their sensitive data.

Analyst 207
Network operations environment with servers, routers, and cables, showing a data stream being intercepted.

Cloud Providers' Global Namespace Flaw Enables Bucket Hijacking

A newly discovered flaw in cloud providers' global namespace has been exploited in a simple yet powerful bucket hijacking technique, allowing attackers to redirect sensitive data streams into their own accounts. This alarming vulnerability affects multiple services across major cloud providers.

Analyst 207
Security analysts work urgently at desks in a brightly-lit operations center surrounded by multiple screens displaying data…

Cybersecurity's 72-Minute Challenge

The clock is ticking: in the blink of an eye, just 72 minutes, attackers can breach your defenses and make off with your data, highlighting a daunting speed gap between threat actors and security teams. This alarming acceleration demands a serious rethink of traditional security operations.

Analyst 207
Researcher's workspace with laptop, notes, and diagrams on whiteboard and paper.

AI Skills Marketplace Exposes Security Gaps

A recent audit of OpenClaw's AI skills marketplace uncovered a staggering 250,706 behavioral deviations in 49,943 agent "skills", revealing a significant gap between what AI skills claim to do and what they actually do. This alarming mismatch highlights the urgent need for robust security measures, such as Palo Alto Networks' Unit 42's Behavioral Integrity Verification (BIV) solution.

Analyst 207
Rows of servers and storage systems in a cloud data center or server room.

Attackers Target Cloud Logging Services for Defense Evasion and Continuous Visibility

Cloud logging services, like AWS CloudTrail and Google Cloud Logging, are a treasure trove of insights into your cloud environment - but they're also a prime target for attackers looking to erase their tracks or gain continuous visibility into your operations. By manipulating these services, adversaries can create persistent blind spots that leave you vulnerable.

Analyst 207
Network device with cables on a rack in a well-lit technology room.

Palo Alto Networks Warns of Active PAN-OS Vulnerability Exploitation

Palo Alto Networks has sounded the alarm on a critical PAN-OS vulnerability, CVE-2026-0257, that's being actively exploited by threat actors to bypass authentication and gain unauthorized access to VPN connections. This security gap could allow attackers to circumvent controls and initiate their own VPN sessions, putting your network at risk.

Analyst 207
Cluttered home office desk with Mac computer and blurred screen, suburban neighborhood visible through window.

Malvertising Campaign Spreads FlutterShell Backdoor to macOS Users

macOS users beware: a sneaky malware called FlutterShell is spreading through malicious ads and infected desktop apps, allowing hackers to take control of your device and steal sensitive data. This stealthy backdoor can execute commands, access files, and even siphon off browser session info - all while masquerading as legitimate software.

Analyst 207